Website URL
<private>
Chevereto version
3.10.7
Description of the issue
Last year we had our Chevereto self hosted on our own vps and all the images stored at S3. In front of the site we had CloudFlare because we used it for https and to reduce the amount of data transfer from S3.
Last fall there occurred several cases when users reported that their images appeared on some other users account and vice versa. Also the preview images could be other than the real image.
I opened a tech support ticket here. The explanation was that it might be a server-related flaw so it wasn't covered with this support. Also it was thought the cache was guilty of false preview images.
I couldn't continue to let users to upload any more images so I closed the upload. I figured out I should move our site to TMD Hosting to be sure the server misconfiguration or such can be ruled out.
TMD Hosting refused to ingest our images (10,5 GB) so we set up a new SFTP vps and copied all the images from S3 there. It was set up to be in the same subdomain url as the S3 image storage earlier. S3 was switched off and the new vps on in the Chevereto's settings for external storage.
TMD Hosting transferred the site to their servers. They installed a Let'sEncrypt ssl so the CloudFlare was not necessary.
The new site functioned ok, all the images could be browsed, etc. and there was not any new mixed account images, just the old ones.
I asked them to set the correct email settings and update Chevereto to the latest revision, because they market the hosting as "fully managed Chevereto approved hosting". They made the update.
Today I decided to test everything is working ok. I made a new album in my own account and uploaded 381 images to it. The upload went fine and all the images appeared in my new album.
However, they also appeared on at least one other users albums (several albums) and they seem to have overwritten some content there. I purged the image cache of Google Chrome, but it didn't change anything. The images can still be seen on the both accounts.
<private>
Chevereto version
3.10.7
Description of the issue
Last year we had our Chevereto self hosted on our own vps and all the images stored at S3. In front of the site we had CloudFlare because we used it for https and to reduce the amount of data transfer from S3.
Last fall there occurred several cases when users reported that their images appeared on some other users account and vice versa. Also the preview images could be other than the real image.
I opened a tech support ticket here. The explanation was that it might be a server-related flaw so it wasn't covered with this support. Also it was thought the cache was guilty of false preview images.
I couldn't continue to let users to upload any more images so I closed the upload. I figured out I should move our site to TMD Hosting to be sure the server misconfiguration or such can be ruled out.
TMD Hosting refused to ingest our images (10,5 GB) so we set up a new SFTP vps and copied all the images from S3 there. It was set up to be in the same subdomain url as the S3 image storage earlier. S3 was switched off and the new vps on in the Chevereto's settings for external storage.
TMD Hosting transferred the site to their servers. They installed a Let'sEncrypt ssl so the CloudFlare was not necessary.
The new site functioned ok, all the images could be browsed, etc. and there was not any new mixed account images, just the old ones.
I asked them to set the correct email settings and update Chevereto to the latest revision, because they market the hosting as "fully managed Chevereto approved hosting". They made the update.
Today I decided to test everything is working ok. I made a new album in my own account and uploaded 381 images to it. The upload went fine and all the images appeared in my new album.
However, they also appeared on at least one other users albums (several albums) and they seem to have overwritten some content there. I purged the image cache of Google Chrome, but it didn't change anything. The images can still be seen on the both accounts.